Getting Data In

Reindex old data from zip files

oliverw
New Member

I am trying to recover log data that has aged out of the Splunk index.
I have access to the original log files, they have been individually zipped, one log file per zip file. When our archive script did this originally, Splunk was smart enough to not re-index them. Now I want to re-index them as new files.

I have created a new recovery directory, added a new monitor to inputs.conf, and set crcSalt

[monitor://D:\IISLogs\LogFiles\Recovery]
disabled = 0
crcSalt = <SOURCE>
index = ms_iis
sourcetype = ms:iis:default

This all works fine with new test file, even a zip file, but when I copy one of the old zipped log files, they are not indexed.
If I unzip the log file, it is indexed correctly.
I have a lot of logs to ingest. How can I get Splunk to re-index them without unzipping them?

Tags (3)
0 Karma

p_gurav
Champion

Instead of reindexing can you try restoring archive data. Refer below document:
http://docs.splunk.com/Documentation/Splunk/7.0.2/Indexer/Restorearchiveddata

0 Karma
Get Updates on the Splunk Community!

Technical Workshop Series: Splunk Data Management and SPL2 | Register here!

Hey, Splunk Community! Ready to take your data management skills to the next level? Join us for a 3-part ...

Spotting Financial Fraud in the Haystack: A Guide to Behavioral Analytics with Splunk

In today's digital financial ecosystem, security teams face an unprecedented challenge. The sheer volume of ...

Solve Problems Faster with New, Smarter AI and Integrations in Splunk Observability

Solve Problems Faster with New, Smarter AI and Integrations in Splunk Observability As businesses scale ...